Agent skill

Package Release Audit

by udecode in udecode/kitcn

Audit newer npm package releases against kitcn. An agent skill from udecode/kitcn.

Apache-2.0Auto-check passedDevelopment

Install Package Release Audit

skills CLI
$ npx skills add udecode/kitcn --skill package-release-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install udecode/kitcn package-release-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/package-release-audit .claude/skills/package-release-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
package-release-audit
GitHub stars
450
Token cost
~2k tokens
SKILL.md length
676 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit newer npm package releases against kitcn. An agent skill from udecode/kitcn.

  • Works in 7 steps: Establish Package, Current, And Target… → Read Changelogs And Release Notes → Read The Upstream Diff With gh → …
  • Checking whether a newer dependency version unlocks kitcn improvements
  • SKILL.md covers Rules, 1. Establish Package, Current,…, 2. Read Changelogs And Release… and 3. Read The Upstream Diff With…, plus 5 more sections
  • Calls gh, git and rg

What it does

Package Release Audit is an agent skill from udecode/kitcn. Audit newer npm package releases against kitcn. Use when checking whether a newer dependency version unlocks kitcn improvements, compatibility work, CLI/agent workflows, or cleanup of local package-specific hacks. Reads package changelogs, GitHub releases, upstream diffs, and local kitcn usage before delegating an implementation PR through task.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. It works with npm and GitHub. The repository describes itself as: Convex + Better Auth + tRPC + Drizzle + TanStack Query + shadcn. The licence is Apache-2.0.

When your agent uses it

  • Checking whether a newer dependency version unlocks kitcn improvements
  • Compatibility work
  • CLI/agent workflows
  • Cleanup of local package-specific hacks

Example prompts

  • “/package-release-audit”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Establish Package, Current, And Target Versions
  2. Read Changelogs And Release Notes
  3. Read The Upstream Diff With gh
  4. Search Kitcn For Leverage
  5. Classify Opportunities
  6. Choose One PR Slice
  7. Delegate Through task

What it can do on your machine

Read from SKILL.md and the folder at commit c6010f5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git
    • rg
    • bun
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Package Release Audit loads about 2k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 676 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from udecode/kitcn at commit c6010f5, republished under its Apache-2.0 licence (© udecode). 676 words, ~1,980 tokens.

Download SKILL.mdSave it as .claude/skills/package-release-audit/SKILL.md (or your agent's skills folder).
name
package-release-audit
description
Audit newer npm package releases against kitcn. Use when checking whether a newer dependency version unlocks kitcn improvements, compatibility work, CLI/agent workflows, or cleanup of local package-specific hacks. Reads package changelogs, GitHub releases, upstream diffs, and local kitcn usage before delegating an implementation PR through `task`.

Package Release Audit

Handle $ARGUMENTS.

Goal: find newer releases for a named package, extract work kitcn can actually use, then delegate one concrete implementation slice to $task so it opens the PR.

Rules

  • Use evidence, not vibes. Read changelog/release sources and a diff.
  • Prefer deleting kitcn glue over adding more glue when upstream fixed the real problem.
  • Do not upgrade a package just because a newer version exists. Ship only a leverageable improvement.
  • Keep the PR slice coherent. One release opportunity per PR unless multiple fixes share the same seam.
  • If no actionable opportunity exists, stop with the evidence. Do not open a vanity PR.

1. Establish Package, Current, And Target Versions

Extract the package name from $ARGUMENTS. If the package name is ambiguous, stop and ask for the exact npm package name.

Find the currently pinned package version:

bash
rg -n '"<package-name>":' package.json packages/**/package.json example/package.json

Find the latest published version and package metadata:

bash
npm view <package-name> version repository homepage dist-tags --json

If $ARGUMENTS names a target version, use it as the upper bound. Otherwise use the latest npm version.

Record:

  • package name
  • current pinned version or range
  • target version
  • every version in the current-exclusive, target-inclusive range when discoverable
  • exact package files that pin or constrain the package
  • repository owner/name inferred from npm metadata

2. Read Changelogs And Release Notes

Prefer official sources in this order:

  1. package repository changelog files
  2. GitHub releases
  3. package docs/blog release pages from npm metadata
  4. npm package metadata only when no richer source exists

Read the repository changelog through gh, not browser scraping, when a GitHub repo is available:

bash
gh api \
  -H "Accept: application/vnd.github.raw" \
  repos/<owner>/<repo>/contents/CHANGELOG.md

If that path is missing, discover likely changelog paths:

bash
gh api repos/<owner>/<repo>/git/trees/HEAD?recursive=1 \
  --jq '.tree[].path | select(test("(^|/)(CHANGELOG|RELEASES|HISTORY|UPGRADING|MIGRATION|MIGRATIONS)\\\\.(md|mdx|txt)$"; "i"))'

Read GitHub releases:

bash
gh release list --repo <owner>/<repo> --limit 20
gh release view <tag-or-version> --repo <owner>/<repo>

Extract only the sections in range. Reconcile disagreements:

  • Changelog files are package-facing signal.
  • GitHub releases are release-manager signal.
  • Docs/blog pages are product-facing signal.
  • If they disagree, keep both facts and investigate in the diff.

3. Read The Upstream Diff With gh

Use a local upstream clone for navigation, creating it only if missing:

bash
test -d ../<repo-name>/.git || gh repo clone <owner>/<repo> ../<repo-name>
git -C ../<repo-name> fetch origin main --tags

Find refs for the current and target versions. Prefer tags if they exist:

bash
git -C ../<repo-name> tag -l "*<version>*" | sort
git -C ../<repo-name> log --all --oneline -- '*package.json' '*CHANGELOG*'

If tags are unclear, inspect version-bump commits in the package's package.json or changelog and use the commit before/after each version bump.

Read the compare through gh:

bash
gh api \
  repos/<owner>/<repo>/compare/<base-ref>...<target-ref> \
  --jq '.files[] | select(.filename | test("package|src|cli|server|client|auth|plugin|adapter|schema|migration|agent|mcp|codegen|docs|CHANGELOG"; "i")) | {filename,status,patch}'

If the compare is too large, narrow locally after proving the refs:

bash
git -C ../<repo-name> diff <base-ref>..<target-ref> -- \
  . ':!**/node_modules/**' ':!**/dist/**' ':!**/build/**'

4. Search Kitcn For Leverage

Search for local package integration points and hacks:

bash
rg -n "<package-name>|<package-import>|<package-domain-term>|TODO|workaround|hack|temporary|shim|compat|adapter|plugin|peer|version" \
  packages www .agents docs test tooling

Also search institutional notes before proposing work:

bash
rg -i --files-with-matches "<package-name>|<package-domain-term>|upgrade|compat|agent|cli|bootstrap|adapter|plugin|peer|version" docs/solutions

Read relevant hits, especially notes about:

  • package-specific wrappers, adapters, plugins, or generated code
  • peer dependency ranges and scaffold pins
  • CLI or agent workflow workarounds
  • non-interactive, deterministic, or machine-readable behavior
  • docs/skill sync for package guidance
  • dirty hacks that might be obsolete after the upstream release
Show full SKILL.md (244 more words)Show less

5. Classify Opportunities

For each release item, classify it:

  • feature: new package API, CLI command, runtime behavior, integration, or platform feature kitcn can expose.
  • compatibility: required work to keep kitcn working with the new version.
  • agentic: upstream change that improves non-interactive, deterministic, machine-readable, MCP, CLI, or automation flows.
  • cleanup: upstream change that lets kitcn delete a workaround, shim, fallback, prompt handling, wrapper, patch, or doc warning.
  • docs: upstream change that only affects user-facing docs, setup guidance, or skills.
  • no-op: interesting upstream change with no kitcn action.

For every non-no-op, include:

  • changelog or release evidence
  • diff evidence
  • kitcn file(s) affected
  • expected implementation seam
  • verification command(s)
  • confidence

Bias toward agentic and cleanup; kitcn exists to make dependencies sharper for humans and agents, not to mirror every upstream bullet.

6. Choose One PR Slice

Pick the highest-leverage slice using this order:

  1. compatibility breakage
  2. delete dirty hack made obsolete upstream
  3. agentic CLI/tooling unlock
  4. product feature kitcn can expose cleanly
  5. docs or skill-only update

If the winning slice touches published package code, the delegated task must update the active changeset and run bun --cwd packages/kitcn build.

If it touches scaffold templates, the delegated task must run bun run fixtures:sync and bun run fixtures:check.

7. Delegate Through task

Load $task with a prompt in this exact shape:

md
Implement this package release opportunity.

Package: <package-name>
Current version/range: <version>
Target version: <version>

Opportunity: <one-sentence selected slice>
Class: <feature | compatibility | agentic | cleanup | docs>

Evidence:
- Changelog/release notes: <short citation or summary>
- Upstream diff: <refs and files>
- Kitcn evidence: <local files and docs/solutions notes>

Implementation:
- <specific files or seams to inspect first>
- <expected code/doc/test shape>

Acceptance:
- <tests/checks>
- <package build if packages/kitcn changes>
- <fixtures commands if scaffold output changes>
- open the PR after verification

Do not preserve obsolete package workarounds if the upstream release removes
the need for them. Hard cut the hack.

Then follow task until the PR exists or a real blocker is proven.

Output

Before delegation, keep the audit terse:

md
Package: <package-name>
Current: <version>
Target: <version>

| Class | Opportunity | Evidence | Decision |
| --- | --- | --- | --- |
| cleanup | ... | ... | selected |

Delegating to task: <selected slice>

After task finishes, use its final handoff format.

© udecode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/package-release-audit of udecode/kitcn.

Open the folder on GitHubat commit c6010f5

Compare with similar skills

Package Release Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Package Release Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Package Release Audit this skilludecode/kitcn450—~2kAutomated safety check: PassApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.5k—~3.8kAutomated safety check: PassMIT
Version ReleaseNG-ZORRO/ng-zorro-antd9.2k—~3.1kAutomated safety check: PassMIT
Release Roundethereumjs/ethereumjs-monorepo2.8k—~2kAutomated safety check: PassNone

Similar skills

  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.5k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Release Round

    ethereumjs/ethereumjs-monorepo

    Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.

    2.8k GitHub stars~2k tokensUpdated 19 days ago
    DevelopmentAuto-check passed
  • Ccb GitHub

    SeemSeam/claude_codex_bridge

    Maintain this CCB project's GitHub-facing release and npm publication surface.

    3.5k GitHub stars~4.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from udecode/kitcn

All 33 skills in this repo
  • Walkthrough

    udecode/kitcn

    Create a short annotated visual walkthrough from real final-state screenshots or rendered artifacts.

    450 GitHub stars~1.6k tokensUpdated 6 days ago
    Auto-check passed
  • Avoid Feature Creep

    udecode/kitcn

    Prevent feature creep when building software, apps, and AI-powered products.

    450 GitHub stars~2.7k tokensUpdated 6 days ago
    Auto-check passed
  • Changeset Resolve

    udecode/kitcn

    Repair an unreleased .changeset/.md file so it matches the real branch delta against main.

    450 GitHub stars~922 tokensUpdated 6 days ago
    Auto-check passed
  • Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.

    450 GitHub stars~1.8k tokensUpdated 6 days ago
    Auto-check passed
  • Jotai X

    udecode/kitcn

    A skill your agent uses when working with Jotai X stores (createAtomStore), accessing state in components or callbacks, persisting state to cookies or localStorage

    450 GitHub stars~3.7k tokensUpdated 6 days ago
    Auto-check passed
  • Linear Backlog

    udecode/kitcn

    Run a scoped Linear backlog autonomously as a sequence of maximal safe parallel batches by composing orchestrator, autogoal, and task.

    450 GitHub stars~3.1k tokensUpdated 6 days ago
    Auto-check passed

Works with

Categories

Questions about Package Release Audit

What does Package Release Audit do?

Audit newer npm package releases against kitcn. An agent skill from udecode/kitcn. Package Release Audit is an agent skill from udecode/kitcn. Audit newer npm package releases against kitcn.

When should I use Package Release Audit?

Package Release Audit fits situations like: checking whether a newer dependency version unlocks kitcn improvements; compatibility work; CLI/agent workflows; cleanup of local package-specific hacks.

How do I install Package Release Audit in Claude Code?

Run `npx skills add udecode/kitcn --skill package-release-audit -a claude-code`. Or copy the skill folder (.agents/skills/package-release-audit in udecode/kitcn) into .claude/skills/package-release-audit in your project. Claude Code loads it when a task matches its description.

How do I install Package Release Audit in Codex?

Run `npx skills add udecode/kitcn --skill package-release-audit -a codex`. Or copy the skill folder (.agents/skills/package-release-audit in udecode/kitcn) into .agents/skills/package-release-audit in your project. Codex loads it when a task matches its description.

Can I use Package Release Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/kitcn --skill package-release-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/package-release-audit, .gemini/skills/package-release-audit, .github/skills/package-release-audit and .opencode/skills/package-release-audit in your project.

What does Package Release Audit need to run?

Going by SKILL.md and its folder, Package Release Audit needs the command-line tools its instructions call (gh, git, rg, bun and npm).

Does Package Release Audit access the network?

SKILL.md contains no URLs. Its commands use gh, git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Package Release Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Package Release Audit use?

Package Release Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Package Release Audit use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Package Release Audit?

Skills that share tags, products or a category with Package Release Audit: Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Hunk Release Workflow (modem-dev/hunk, 9.5k stars) and Version Release (NG-ZORRO/ng-zorro-antd, 9.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Package Release Audit?

udecode (a GitHub organization) maintains it in udecode/kitcn, which has 450 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: udecode/kitcn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.